{
  "id": "package-url-inspect",
  "name": "Package URL Inspect",
  "description": "Parse a bounded Package URL and normalize generic syntax: type/qualifier case, percent encoding, qualifier order. Preserves name/version case; no ecosystem rules or registry validation. Strict subset rejects empty/dot path segments, whitespace, raw reserved characters, malformed UTF-8, and duplicate qualifiers.",
  "category": "supply-chain",
  "priceUsd": "0.003",
  "pricingStatus": "proposed-unverified",
  "pricing": {
    "unit": "one successful operation call",
    "proposedNominalUsd": "0.003",
    "sixDecimalTokenBaseUnits": "3000",
    "subscription": false,
    "includesPayerWalletOrNetworkFees": false,
    "liveQuoteVerified": false,
    "condition": "Actual SDK challenge is authoritative only within the caller's explicit authorization; configured six-decimal token peg is an operator assertion, not a conversion guarantee."
  },
  "intents": [
    "parse package URL",
    "normalize PURL syntax",
    "inspect package coordinates"
  ],
  "whenToUse": [
    "Extract package type, namespace, version, qualifiers, and subpath without network access",
    "Normalize percent escapes and qualifier ordering inside the advertised subset"
  ],
  "whenNotToUse": [
    "Full ECMA-427 or ecosystem-specific PURL validation/canonicalization",
    "Registry existence checks or fetching package artifacts"
  ],
  "capabilities": [
    "Generic syntax profile with explicit ecosystemRulesApplied=false",
    "Sorted unique qualifier keys; UTF-8 decoding; no fetch"
  ],
  "related": [
    "sbom-inventory",
    "sbom-diff"
  ],
  "limits": {
    "inputBytes": 100000,
    "jsonNodes": 12000,
    "jsonDepth": 24,
    "outputBytes": 300000,
    "purlCharacters": 4096,
    "namespaceSegments": 32,
    "qualifiers": 32,
    "subpathSegments": 32
  },
  "errorCodes": [
    "INVALID_INPUT",
    "INVALID_JSON",
    "INPUT_LIMIT",
    "COMPLEXITY_LIMIT",
    "UNSAFE_KEY",
    "OUTPUT_LIMIT",
    "INVALID_PURL"
  ],
  "requirementsProfile": {
    "format": "declared-requirements-v1",
    "facts": {
      "execution.suppliedCode": false,
      "execution.remoteMutation": false,
      "execution.llmInference": false,
      "execution.paidMcp": false,
      "verification.semanticTruth": false,
      "verification.sourceAuthenticity": false,
      "verification.liveVulnerabilities": false,
      "numbers.arbitraryPrecisionJson": false,
      "numbers.model": "ieee754-binary64",
      "privacy.requestBodyPersisted": false,
      "execution.deterministic": true,
      "execution.networkAccess": false,
      "privacy.resultBodyPersisted": false,
      "payment.x402": true,
      "payment.mpp": true,
      "operation.id": "package-url-inspect",
      "operation.category": "supply-chain",
      "limit.httpRequestBytes": 131072,
      "limit.requestBytes": 100000,
      "limit.responseBytes": 524288,
      "limit.resultBytes": 300000,
      "limit.jsonDepth": 24,
      "limit.jsonNodes": 12000,
      "input.purl.maxLength": 4096,
      "input.purl.minLength": 1
    },
    "unknownPolicy": "Undeclared requirements are unknown, never compatible. Matching declared facts does not establish semantic fit or input validity.",
    "preflight": "/preflight"
  },
  "documentation": "/reference/tools/package-url-inspect.md",
  "serviceContract": "/reference/services/package-url-inspect.json",
  "errors": [
    {
      "status": 400,
      "meaning": "Malformed JSON, missing/invalid idempotency key, or payment identifier mismatch",
      "retry": "Correct the request before payment"
    },
    {
      "status": 402,
      "meaning": "Payment challenge or rejected payment",
      "retry": "Use official protocol SDK; inspect payment outcome before another payment"
    },
    {
      "status": 409,
      "meaning": "Idempotency conflict, duplicate proof, or PAYMENT_UNCERTAIN",
      "retry": "Keep original key, body, and proof; reconcile uncertainty with operator; never blindly repay"
    },
    {
      "status": 413,
      "meaning": "Input or generated output too large",
      "retry": "Reduce input; no payment attempted for validation failure"
    },
    {
      "status": 415,
      "meaning": "Unsupported media type or compression",
      "retry": "Send uncompressed application/json"
    },
    {
      "status": 422,
      "meaning": "Schema or service-specific semantic validation failure",
      "retry": "Correct input using returned error code; no payment attempted"
    },
    {
      "status": 429,
      "meaning": "Request/payment-attempt rate exceeded",
      "retry": "Wait for rate limit window; preserve existing payment identity"
    },
    {
      "status": 503,
      "meaning": "Payment configuration/provider/state unavailable, or live DNS preparation failed before settlement",
      "retry": "Check readiness; DNS preparation failures may retry the identical key/body/credential only; uncertainty requires reconciliation"
    }
  ],
  "numericPrecision": "JavaScript IEEE-754 numbers; use strings for large integer IDs/exact decimals where the schema accepts strings. No lossless numeric parsing.",
  "paymentWorkflow": {
    "discoveryOnly": false,
    "supportedProtocols": [
      "x402",
      "mpp"
    ],
    "x402": {
      "credentialHeader": "PAYMENT-SIGNATURE",
      "challengeHeader": "PAYMENT-REQUIRED",
      "receiptHeader": "PAYMENT-RESPONSE",
      "version": 2,
      "scheme": "exact",
      "paymentIdentifier": "payment-identifier extension MUST equal the HTTP Idempotency-Key",
      "sdk": "@x402/core with @x402/evm"
    },
    "mpp": {
      "supported": true,
      "credentialHeader": "Authorization",
      "challengeHeader": "WWW-Authenticate",
      "receiptHeader": "Payment-Receipt",
      "method": "tempo",
      "intent": "charge",
      "sdk": "mppx",
      "tokenDecimals": 6
    },
    "steps": [
      "Check configured readiness and the exact service schema",
      "Generate a fresh random Idempotency-Key for this operation; never use a discovery probe fixture for purchases",
      "Send valid input without a credential to obtain the official protocol challenge",
      "Use the official SDK and authorized wallet to fulfill the challenge",
      "Retry only with identical key, body, protocol and credential",
      "On PAYMENT_UNCERTAIN stop and request operator reconciliation; never blindly pay again"
    ],
    "versionedRetries": "Request fingerprint includes service release version. Retries across a version upgrade can conflict; coordinate upgrades outside the 24-hour replay window and reconcile pending attempts.",
    "docs": "/llms.txt"
  },
  "method": "POST",
  "paths": {
    "x402": "/v1/x402/package-url-inspect",
    "mpp": "/v1/mpp/package-url-inspect"
  },
  "inputSchema": {
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "properties": {
      "purl": {
        "type": "string",
        "minLength": 1,
        "maxLength": 4096
      }
    },
    "required": [
      "purl"
    ],
    "additionalProperties": false
  },
  "outputSchema": {
    "type": "object",
    "required": [
      "operation",
      "version",
      "result",
      "provenance"
    ],
    "properties": {
      "operation": {
        "const": "package-url-inspect",
        "type": "string"
      },
      "version": {
        "const": "0.29.0",
        "type": "string"
      },
      "result": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "normalized": {
            "type": "string",
            "maxLength": 12288
          },
          "type": {
            "type": "string",
            "maxLength": 100
          },
          "namespace": {
            "maxItems": 32,
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 2048
            }
          },
          "name": {
            "type": "string",
            "maxLength": 2048
          },
          "version": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 2048
              },
              {
                "type": "null"
              }
            ]
          },
          "qualifiers": {
            "maxItems": 32,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "key": {
                  "type": "string",
                  "maxLength": 100
                },
                "value": {
                  "type": "string",
                  "maxLength": 2048
                }
              },
              "required": [
                "key",
                "value"
              ],
              "additionalProperties": false
            }
          },
          "subpath": {
            "maxItems": 32,
            "type": "array",
            "items": {
              "type": "string",
              "maxLength": 2048
            }
          },
          "profile": {
            "type": "string",
            "const": "generic-syntax-subset-v1"
          },
          "ecosystemRulesApplied": {
            "type": "boolean",
            "const": false
          }
        },
        "required": [
          "normalized",
          "type",
          "namespace",
          "name",
          "version",
          "qualifiers",
          "subpath",
          "profile",
          "ecosystemRulesApplied"
        ],
        "additionalProperties": false
      },
      "provenance": {
        "type": "object",
        "required": [
          "inputSha256",
          "outputSha256",
          "deterministic",
          "externalRequests"
        ],
        "properties": {
          "inputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "outputSha256": {
            "type": "string",
            "pattern": "^[a-f0-9]{64}$"
          },
          "deterministic": {
            "const": true
          },
          "externalRequests": {
            "const": 0
          }
        }
      }
    },
    "additionalProperties": false
  },
  "exampleInput": {
    "purl": "pkg:npm/%40acme/worker-kit@1.2.0?repository_url=https%3A%2F%2Fregistry.example&arch=x64#dist/index.js"
  },
  "exampleResponse": {
    "operation": "package-url-inspect",
    "version": "0.29.0",
    "result": {
      "normalized": "pkg:npm/%40acme/worker-kit@1.2.0?arch=x64&repository_url=https%3A%2F%2Fregistry.example#dist/index.js",
      "type": "npm",
      "namespace": [
        "@acme"
      ],
      "name": "worker-kit",
      "version": "1.2.0",
      "qualifiers": [
        {
          "key": "arch",
          "value": "x64"
        },
        {
          "key": "repository_url",
          "value": "https://registry.example"
        }
      ],
      "subpath": [
        "dist",
        "index.js"
      ],
      "profile": "generic-syntax-subset-v1",
      "ecosystemRulesApplied": false
    },
    "provenance": {
      "inputSha256": "5c4dfe4d67dbd3df697be9f5119fee7da589fd2f05cf0bf7ea10c6b860c04659",
      "outputSha256": "99448916979697e5c9fff32ebdecee9d452e113f95e03134503022f51e86aca1",
      "deterministic": true,
      "externalRequests": 0
    }
  },
  "requiredHeaders": {
    "Content-Type": "application/json",
    "Idempotency-Key": "random 16–128 character operation identifier"
  },
  "fixedExample": "/reference/examples/package-url-inspect.json",
  "execution": {
    "deterministic": true,
    "externalRequests": 0,
    "maxExternalRequests": 0,
    "resultSnapshotPersisted": false,
    "fixedExampleIsIllustrativeSnapshot": false,
    "requiresPayment": true,
    "supportsMcpExecution": false
  },
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  }
}
